Topic cluster

AI compliance: AI Act, ISO 27001, and audit readiness

Quick answer

AI deployment compliance goes beyond NIS2, it also covers the AI Act (high-risk system obligations from 2 August 2026), ISO 27001, and GDPR. Compliance isn't declarations but artifacts: technical documentation, logs, risk analysis, and control mappings that survive an audit.

AI compliance: AI Act, ISO 27001, and audit readiness

This cluster shows how to turn regulatory requirements into audit readiness for AI deployments. We cross-map NIS2, the AI Act, and ISO 27001, because the same controls (information classification, logging, access management) serve several regimes at once if you design them well. We spell out which ISO 27001 controls are worth mapping to an AI vendor today and which 7 documents you actually produce for an auditor. The key difference from competitors: we don't leave you with a list of obligations, we show how on-prem architecture simplifies meeting them (human oversight, data isolation, full logging). We monitor and date AI Act and Digital Omnibus deadlines.

// notes in this topic (9)
Cross-mapping NIS2, AI Act, GDPR and ISO 27001 without duplication

Four regimes, one set of evidence, and from autumn 2026 a fifth for anyone making products with software. How to map NIS2, AI Act, GDPR, ISO 27001 and the CRA onto one control matrix, evidence per control, and how to separate the four reporting clocks.

AI Vendor DPA: 8 Clauses Whose Absence Breaks Your Audit

A vendor's boilerplate DPA stays silent exactly where an auditor looks first. Eight clauses whose absence breaks an NIS2 or GDPR audit: from the sub-processors behind the model API and training use of your data, to logs, breach notice and data deletion.

Frequently asked questions
Is my AI system “high-risk” under the AI Act?

It depends on the use (e.g. HR, scoring, medicine, critical infrastructure). Classification is done per use-case; we describe an assessment pattern.

Is ISO 27001 enough for NIS2?

It doesn't replace it but helps significantly, many controls overlap; we show the mapping.

What do I produce “for the audit”?

Among others: risk analysis, an AI policy, a system register, logs, technical documentation, and evidence of board oversight.

Want to apply this to your case: architecture, compliance, and cost?

→ Book 30 min